Malicious FomoPeek iOS app linked to $580K crypto theft via kernel exploits
In brief
- FomoPeek malicious versions (Sept. 9, 12) escaped iOS sandbox via kernel exploits to access wallet data
- SlowMist traced ~$580K USDT to primary hacker address activated Sept. 15
- Stolen funds moved across blockchains to exchanges including KuCoin and FixedFloat
The Attack Vector
SlowMist's investigation, conducted with the OKX security team, began after receiving reports from users who had suffered asset theft. The firm found that affected FomoPeek versions were released on September 9 and September 12.
The malicious modules introduced into FomoPeek "introduced two malicious modules that could exploit iOS vulnerabilities, gain elevated privileges and access Keychain data and files belonging to other apps," SlowMist said. The exploit framework included eight distinct attack methods and declared support for iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1.
Tracking the Theft
SlowMist's onchain analysis identified a primary hacker address associated with the incident that received approximately 579,984 USDT. The address became active on September 15, three days after the initial malicious release.
Stolen funds moved through multiple blockchain networks before being consolidated and transferred through several addresses and services. Portions of the stolen funds were transferred toward services including FixedFloat, KuCoin and cce.cash.
Remediation
Version 1.3 of FomoPeek, released on September 17, removed the malicious components. The incident underscores the risk of supply-chain compromises targeting mobile app stores, where malicious updates can reach thousands of users before detection.


